Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


I got a load of viruses...easy and hard to delete. HELP?
Goto page Previous  1, 2
 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk
View previous topic :: View next topic  
Author Message
b004u
Advanced Cheater
Reputation: 0

Joined: 06 Jun 2009
Posts: 95

PostPosted: Tue Aug 11, 2009 11:40 am    Post subject: Reply with quote

You need Sandboxie for all dial up users ;]
Back to top
View user's profile Send private message
mark_the_hacker
Grandmaster Cheater Supreme
Reputation: 0

Joined: 26 Oct 2007
Posts: 1020
Location: CEF

PostPosted: Wed Aug 12, 2009 7:05 am    Post subject: Reply with quote

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:48:17 PM, on 8/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\DAP\DAP.EXE
C:\WINDOWS\AhnRpta.exe
C:\Documents and Settings\B-Boy MQ\My Documents\Downloads\Installers\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mofunzone.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Services] service.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
O4 - HKCU\..\Run: [cdoosoft] C:\DOCUME~1\B-BOYM~1\LOCALS~1\Temp\herss.exe
O4 - S-1-5-18 Startup: G Connection.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: G Connection.lnk = ? (User 'Default user')
O4 - Startup: G Connection.lnk = ?
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Add to Media Manager... - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{46C6496C-E2F7-4E8A-8F7B-1B8B92BB6E59}: NameServer = 64.193.123.12 202.88.64.61
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

--
End of file - 4569 bytes
Back to top
View user's profile Send private message AIM Address Yahoo Messenger
Saifallofjmr
Grandmaster Cheater Supreme
Reputation: 4

Joined: 02 Apr 2007
Posts: 1450

PostPosted: Wed Aug 12, 2009 8:45 am    Post subject: Reply with quote

Delete these that remain

Code:
Running processes:
C:\WINDOWS\AhnRpta.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mofunzone.com/

F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE

O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe

O4 - HKCU\..\Run: [cdoosoft] C:\DOCUME~1\B-BOYM~1\LOCALS~1
\Temp\herss.exe

O4 - S-1-5-18 Startup: G Connection.lnk = ? (User 'SYSTEM')

O4 - .DEFAULT Startup: G Connection.lnk = ? (User 'Default user')

O4 - Startup: G Connection.lnk = ?

O17 - HKLM\System\CCS\Services\Tcpip\..\{46C6496C-E2F7-4E8A-8F7B-1B8B92BB6E59}: NameServer = 64.193.123.12 202.88.64.61


I can tell you have a DNS trojan, a generic trojan (downloader), a regular ole Trojan (key logger or password stealer eh who knows) so yeah I would highly recommend malaware byte's software it's free and works GREAT!


Also:
Quote:

Ahnrpta.exe is a dangerous trojan/backdoor that can make your system slow or damage your whole system. It also locks your task manager sometimes.

There are several ways to remove this trojan.

You can remove it by downloading stopzilla or regrun or malwarebytes.

Or if you feel like removing Ahnrpta.exe manually, you can follow this steps:

1. Download REG UNLOCKER
2. Execute reg unlocker (select all options) and as quick as you can, open the task manager (CTR+ ALT +DEL) and kill the process EXPLORER.EXE (don’t worry if all programs start closing and you end with the task manager alone, that is the point)
3. Using the task manager kill the process AhnRpta.exe which is the virus of course you’ll have to do this dozens of times thru this tutorial, because it keeps starting itself again
4. run REGUNLOCKER again. With the task manager go to Applications–> New Task and write “explorer” (without quotes) Remember step 4. Now in the explorer window go to Tools — Folder Options — View and select “show hidden files and folders” accept and go to the task manager and kill “explorer.exe” there.
5. Dont forget step 4. Now, you only have open the task manager in the tab applications click New Task and write
“msconfig” without quotes, (never forget step 4) go to the start tab and look for olhrwef, deselect it, apply, but don’t restart the system, no yet.(step 4), now in the task manager, go to applications – New Task and write “regedit” without quotes. Browse the following path

* HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSI… F-882A-4526-8C08-51278EA437C1}
* HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSI… F-882A-4526-8C08-51278EA437C1}\InprocSer…
* HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSI… F-882A-8C08-4526-51278EA437C1}

the last part can vary a little in each computer, but the firts dozen of numbers will be the same. Delete the keys (I mean, delete the last folder for example {BB4C402F-882A-4526-8C08-51278EA437C1} don’t delete the root folders or you will completly screw up your system.

also browse to

# [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\W... entVersion\Explorer\ShellExecuteHooks]
* {BB4C402F-882A-4526-8C08-51278EA437C1} = “hook dll rising”

and delete the key… be careful in this part you don’t have to delete the complete folder, in the right pane look for the “hook dll rising” part and delete that one only.

Don’t forget step 4.

You can closes the registry and go back to the task manager. New task, click browse and go to

“c:\windows\” you will find the file “AhnRpta.exe” delete it.

Now go to “C:\WINDOWS\system32″ look for the file “olhrwef” and delete it (note: I didn’t found it in my pc but this part was in the original tutorial that I followed).

Also delete the following files in that folder

afmain0.dll
afmain1.dll
afmain2.dll


Also "regunlocker" is at this download link: http://download550.mediafire.com/ydjjonwl0y0g/djynmsmdmx1/reg.rar

it's just 73KB so your good on downloading it[/code]

___________________________________________________________

* Version: 1.40
* File Size: 3.75 MB
* Operating Systems: Microsoft ® Windows 2000, XP, Vista.
* Languages Available: English, Albanian, Arabic, Bosnian, Bulgarian, Catalan, Chinese Simplified, Chinese Traditional, Croatian, Czech, Danish, Dutch, Estonian, Finnish, French, German, Greek, Hungarian, Italian, Koraen, Latvian, Macedonian, Norwegian, Polish, Portuguese, Romanian, Russian, Serbian, Slovak, Slovenian, Spanish, Swedish, Turkish, Ukrainian.



Malwarebytes Anti-Malware's download URL: http://software-files.download.com/sd/LlOs3cOZVKpFVqULtiI3wwTAbF2BkipL5WkUKwhJipvlSNFsJYrLKIftZ2qTdnGitrOmso8bPVKt3cSXvHYpkc_yk3tMT7nr/software/11091568/10804572/3/mbam-setup.exe?lop=link&ptype=1901&ontid=8022&siteId=4&edId=3&spi=7793c61bd69d67995c4445f40a492867&pid=11091568&psid=10804572

_________________

Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk All times are GMT - 6 Hours
Goto page Previous  1, 2
Page 2 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites